CVE-2026-35349 is a vulnerability in the rm utility of uutils coreutils that allows attackers to bypass the --preserve-root protection mechanism, which is designed to prevent accidental deletion of the root filesystem. The flaw stems from improper root directory identification, relying on string-based path comparison rather than device and inode number verification. An attacker can exploit this by creating a symbolic link pointing to the root directory and leveraging it with rm, potentially causing unintended recursive deletion of the entire root filesystem. The vulnerability presents medium severity with a CVSS score of 6.7, requiring local access but no special privileges or user interaction. The attack has high impact potential, affecting both system integrity and availability through filesystem destruction, though confidentiality is not compromised. The local attack vector and higher complexity requirements provide some friction to exploitation. This vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.000140000 indicates minimal probability of exploitation compared to other disclosed vulnerabilities. Community attention remains low, and no public exploit code has been widely circulated, suggesting this remains primarily a theoretical risk at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 0.7.0CPE match | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* | ||
< 0.7.0CPE matchmatch criteria | cpe:2.3:a:uutils:coreutils:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.